Enterprise SaaS
SOC 2, ISO 27001, and customer trust at scale
List of 19 designated critical ICT third-party providers published by the EBA, EIOPA and ESMA on 18 November 2025 under Article 31(9) of Regulation (EU) 2022/2554.
Enterprise SaaS companies must demonstrate security compliance to win and retain customers. Thalorin enables SaaS companies to efficiently achieve SOC 2, ISO 27001, and customer-specific security requirements through automated evidence collection and continuous compliance monitoring.
On 18 November 2025 the European Supervisory Authorities published the first list of designated critical ICT third-party providers under the Digital Operational Resilience Act, and nineteen named providers came under the direct supervision of the same authorities that supervise their customers. The designation matters less than what surrounds it. Every financial entity in the EU maintains a Register of Information naming each ICT provider it uses, the functions those providers support and the subcontracting chain behind them, filed with its national competent authority. A software vendor selling into that market appears by name in someone else's regulatory return.
The contract has stopped being a negotiation in places it used to be one. Chapter VI of the EU Data Act has applied since 12 September 2025 and writes its own terms into every data processing service agreement: notice for initiating a switch capped at two months, a mandatory maximum transitional period of thirty calendar days in which the switch must complete, a data-retrieval period of at least thirty days after that, and a duty to remove contractual, technical and organisational obstacles to leaving. Switching charges disappear entirely on 12 January 2027.
What gets missed is that these obligations arrive through legal review rather than through the security programme. A signed DORA Article 30 addendum commits the vendor to audit rights, exit testing and notice before a material subcontractor changes, and none of it becomes a control with an owner and an evidence trail. The first person to notice the gap is usually a customer's examiner rather than an auditor, because the commitment was made to the customer and the customer is the one being supervised on it.
Thalorin holds a contractual commitment against the agreement that created it rather than in a register beside it. A clause requiring notice before a subprocessor changes resolves to the subprocessor record and to the notification control that has to fire, so the promise is testable rather than merely written; and the same control state answers a CAIQ submission, a bespoke enterprise questionnaire and a diligence request without being restated three times in three formats.
Technology companies must prove their security
Named in your customer's regulatory return
EU financial entities record every ICT provider, the functions supported and the subcontracting chain in a Register of Information filed with their national competent authority. Errors in that entry are your customer's supervisory problem and your commercial one.
Contract terms set by statute
The EU Data Act caps switching notice at two months, caps the transitional period at thirty calendar days and removes switching charges from 12 January 2027. These are not clauses a sales team can trade away for a longer term.
Subcontracting is assessed before it happens
Commission Delegated Regulation (EU) 2025/532 requires a financial entity to assess and control subcontracting of services supporting critical or important functions. In practice that lands on the vendor as a condition on changing material subcontractors at all.
Uniform technical rules, uneven supervision
Commission Implementing Regulation (EU) 2024/2690 binds cloud computing service providers directly, with no national transposition. The Directive around it needed transposing by 17 October 2024, and the Commission has been running infringement proceedings against Member States that missed it ever since.
How Thalorin helps
SOC 2 Type II automation
Set the observation window per product and per legal entity, so a report scoped to one platform does not silently absorb an acquired codebase the service auditor was never shown.
ISO 27001 certification support
Keep the Statement of Applicability attached to the ISMS scope statement, so adding a region or a hosting provider surfaces as a scope change rather than at the surveillance audit.
Customer security questionnaires
Answer from control state instead of from the last questionnaire, and produce CAIQ v4.0 and v4.1 responses from one underlying record while the CSA STAR Registry accepts both.
Trust center integration
Feed the public trust page from the same record, so a listed report status, certificate scope or subprocessor entry expires with the evidence behind it rather than outliving it on a page nobody owns.
Continuous control monitoring
Detect drift against the technical requirements in the Annex to Commission Implementing Regulation (EU) 2024/2690, which binds cloud computing service providers directly across the Union.
Vendor due diligence response
Carry DORA Article 30 clauses, audit rights and subcontracting notice as obligations against the agreement that imposed them, so diligence is answered from the obligation record rather than from a contracts folder.
Enterprise SaaS: common questions
Does DORA apply to us if we are a software vendor and not a financial firm?
Not directly, unless the European Supervisory Authorities designate you a critical ICT third-party provider — nineteen were designated on 18 November 2025 and are supervised directly. It reaches everyone else through the contract. Financial entities must include the Article 30 provisions in ICT agreements, record you in the Register of Information filed with their national competent authority, and assess subcontracting under Commission Delegated Regulation (EU) 2025/532. The obligation is your customer's; the terms are yours to meet or lose the account over.
What does the EU Data Act require us to put in a cloud contract?
Chapter VI has applied since 12 September 2025 and requires switching terms in the agreement itself: notice for initiating a switch of no more than two months, a mandatory maximum transitional period of thirty calendar days in which the switch or the port to on-premises infrastructure must complete, a data-retrieval period of at least thirty days afterwards, and removal of pre-commercial, commercial, technical, contractual and organisational obstacles to switching or to running several providers in parallel. Reduced charges are permitted during the transition and prohibited outright from 12 January 2027.
Do US federal agencies still require the CISA secure software development attestation?
Not as a government-wide requirement. Executive Order 14306 of 6 June 2025 removed the validated attestation requirement, and OMB Memorandum M-26-05, issued 23 January 2026, rescinded the common-form self-attestation mandate created under M-22-18 and directs each agency to set risk-based software and hardware assurance requirements of its own. Agencies may still ask for the form and many do. The demand did not fall — it fragmented across buyers who now each define their own bar.
Should we publish CAIQ v4.0 or v4.1 to the CSA STAR Registry?
Either, for now. The Cloud Security Alliance released Cloud Controls Matrix v4.1 and the corresponding CAIQ v4.1 on 28 January 2026, and the STAR Registry accepts both v4.0 and v4.1 submissions until December 2027, after which new submissions must use v4.1 and existing listings get a further migration period. The practical answer is to hold the control mapping once and emit whichever version a given customer or registry submission asks for.
A customer wants prior approval before we change subprocessors. Is that negotiable?
If the customer is an EU financial entity and your service supports a critical or important function, largely not. Commission Delegated Regulation (EU) 2025/532 has been in force since 22 July 2025 and requires the financial entity to determine and assess subcontracting of those services, which arrives at the vendor as a contractual condition on changing material subcontractors. Treat the subprocessor list as a governed record with notice periods attached, not as a page on the website.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Enterprise SaaS.
See how one evidence artifact satisfies Enterprise SaaS requirements alongside every other framework you carry.